Sign inSign up
Ruby

dhi.io/ruby

Ruby 4.0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.0-alpine-dev, 4.0-alpine3.24-dev, 4.0.7-alpine-dev, 4.0.7-alpine3.24-dev

Index digest:

sha256:969abba6f5cabf0d4196c801f273b85b5d799d909ee6b573e8e62d7622e7e82b

Manifest digest:

sha256:6551586e75565ad1f27667ba008c1093392799d692708f7560a0e0a2acd1e583

Size

93.73 MB

Last pushed

10 days ago

Vulnerabilities

0
1
0
0
2

Support

Active until Mar 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:8192bdb8ebed55177f9c96a2828ad4140169b88c23fc9ecdc8c4e1a5fbb8c184
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:acc7141b1c5e229a34c998ccb4e201e89c91893956290b11bad1b6ff756e0b89
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:4c75f4e0972f0d6cf6be05574c71bba0d6d941c59c588cfb961901743e6aba27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:7cf9d71ae523e310f00136b5714ed2cee28af94f3cff295564ab4717eee35a49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:74a94facf4c3143f5d140519135cb60b88883c7c71baf78cd9755afabc75c101
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:8db8e17d88fe12607e8a35f641cff98db1c607e44c095e79d768f195ae116f26
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:ece5f5032f3557fff6919cb44fc82388ff444ec32f03e60f6905cfd425a5fbc4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:85ed462fb1939a035a746fa9ed1a655e8b614cf7702058b98eda5713f61948e8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:e2bd31e0909ce3d8aba5713b9bd63d39576b95b207383dafa203eeae1216d267
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:6963ae60955b9909f44b7b5440e84078c26ca716d7ef1e93c00bec05112f2434
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:17d2b1339b2ad4e76c9974d1bcc7411d7826f74353769b720e8e74ad50d78916
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:bc3181a20f7066492b9ce57cd076a3ba1994fb480c658eaa2c5ad8ae0fe8f41a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:dc67f0dddd7690379c178a13076065f8efc03dbcdfcdf72df3033a9105ce652d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:81eb6885d381dda17036c9dff161fdbfd68c8883e2f2ef285cc4c57dabd77b3c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:642258997a2cd2442b75f934ae8f5d1456d96e00679b65e283e69a4004e836a1